Help us improve
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
By GRCEngClub
Audit cloud environments for CSA CCM v4.0 compliance: assess organizational readiness across 17 domains, generate CAIQ questionnaires in markdown/JSON/Excel/CSV, create tailored evidence checklists for AWS/Azure/GCP, map controls to ISO 27001/SOC 2/PCI-DSS/NIST, and access implementation guidance for IaaS/PaaS/SaaS models.
npx claudepluginhub grcengclub/claude-grc-engineering --plugin csa-ccmCSA CCM compliance assessment for cloud security controls
Generate CAIQ (Consensus Assessments Initiative Questionnaire) responses
Deep dive guidance on CSA CCM domains and control objectives
Generates comprehensive evidence collection checklists for CSA CCM v4 controls, optimized for cloud-native environments (AWS, Azure, GCP) with STAR attestation guidance.
Map CSA CCM controls to other compliance frameworks
Share bugs, ideas, or general feedback.
Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
SOC 2 Compliance Plugin - Trust Service Criteria expertise, Type I/II assessment support, and control mapping
Prowler for Claude Code — cloud security and compliance skills powered by the Prowler MCP server. Bundles compliance triage and remediation; more skills coming.
GRC (Governance, Risk, and Compliance) domain knowledge — frameworks, controls, audits, evidence, ConMon, cross-framework mappings, document review, and operational workflows. Cloud-agnostic.
Check infrastructure compliance (SOC2, HIPAA, PCI-DSS)
Harness-native ECC plugin for engineering teams - 63 agents, 249 skills, 79 legacy command shims, reusable hooks, rules, MCP conventions, and operator workflows for Claude Code plus adjacent agent harnesses
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
Deploy a serverless trust center to publish your company's compliance posture. Supports AWS deployment with S3, CloudFront, Lambda, DynamoDB, Cognito, and WAF.
SOC 2 Compliance Plugin - Trust Service Criteria expertise, Type I/II assessment support, and control mapping
Essential 8 Plugin - Australian Cyber Security Centre mitigation strategies with 3 maturity levels
GRC connector for GitHub: evaluates repo protections, branch policies, Actions, secret scanning, Dependabot, and deploy keys. Emits findings conforming to schemas/finding.schema.json v1.
GRC Third-Party Risk Management Plugin - Vendor assessments, questionnaire analysis, and risk scoring
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claim